Your information is protected by multiple layers of security. LIENEX restricts portal information to specifically authorized users and uses technical and administrative safeguards designed to protect sensitive medical and legal information.
Portal permissions are enforced by the server. Knowing a client's name, case information, or portal address does not by itself provide access to protected portal information.
LIENEX maintains applicable Business Associate Agreement arrangements with Google for its covered cloud environment. The LIENEX portal uses Google Cloud services within Google's HIPAA-supported infrastructure, including services used for application hosting, data processing, access management, logging, task processing, and deployment.
Google Cloud protects customer content with encryption at rest. LIENEX portal connections are also protected in transit using HTTPS/TLS.
The LIENEX portal is not an open repository of client information. Law-firm access is associated with individually authorized user accounts. Authentication and authorization are required before protected portal information is returned.
New-device authentication uses time-limited, single-use authentication links. A successfully authenticated browser receives its own server-side session, which can expire or be revoked.
Access restrictions are enforced by the LIENEX server rather than relying only on information being hidden in the browser interface. Law-firm users are restricted to information associated with their authorized organization.
Where contact-level access is configured, users can be further restricted to matters associated with their authorized referral or contact scope.
Each trusted browser receives an independent session. LIENEX limits the number of active trusted-browser sessions associated with a portal user and provides mechanisms for revoking access when a device or user should no longer remain authorized.
Authorized users can use Sign Out All Devices to terminate their active portal sessions.
LIENEX records security-relevant portal activity to support administration, investigation, and access oversight. The underlying Google Cloud environment also provides logging and access-control capabilities used as part of LIENEX's security operations.
The portal is designed primarily for treatment, appointment, referral, provider, and related coordination workflows. LIENEX aims to limit portal information to what is reasonably necessary for those workflows rather than using the portal as an unrestricted repository for unnecessary sensitive information.
Email is used for authorized portal invitations, authentication, and selected notifications. Protected portal information is intended to be accessed through the authenticated LIENEX portal rather than unnecessarily distributed through ordinary email.
HIPAA security is an ongoing shared responsibility. LIENEX uses layered technical and administrative safeguards to support secure information handling, while authorized organizations and users remain responsible for protecting their devices, email accounts, credentials, and authenticated portal access.